Sign inSign up

refractionpoint/lc-adapter-zeek

By refractionpoint

•Updated 11 days ago

Image
0

3.5K

refractionpoint/lc-adapter-zeek repository overview

⁠LimaCharlie Adapter + Zeek

This is a simple container running Zeek with a direct feed into LimaCharlie which allows you to quickly deploy Zeek sensors and get retention, alerting and forwarding in the cloud.

This container is available on Docker Hub as refractionpoint/lc-adapter-zeek.

⁠Usage

User needs to define the following environment variables:

  • OID = The LimaCharlie Organization ID
  • IKEY = The LimaCharlie Installation Key
  • NAME = A unique name for the sensor

Optional environment variables:

  • IFACE = The interface to listen on (default: eth0)
  • ZEEK_ARGS = Additional arguments to pass to Zeek

Example command line with Docker:

docker run -it -e OID=aaaaaaaa-bfa1-bbbb-cccc-138cd51389cd -e IKEY=aaaaaaaa-9ae6-bbbb-cccc-5e42b854adf5 -e NAME=zeek -e IFACE=eth0 refractionpoint/lc-adapter-zeek

Tag summary

Content type

Image

Digest

sha256:7fd014100…

Size

239.1 MB

Last updated

11 days ago

docker pull refractionpoint/lc-adapter-zeek